Vulnerability Description
In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Struts | 2.5 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94657Third Party AdvisoryVDB Entry
- https://security.netapp.com/advisory/ntap-20180629-0003/
- https://struts.apache.org/docs/s2-044.htmlMitigationPatchVendor Advisory
- http://www.securityfocus.com/bid/94657Third Party AdvisoryVDB Entry
- https://security.netapp.com/advisory/ntap-20180629-0003/
- https://struts.apache.org/docs/s2-044.htmlMitigationPatchVendor Advisory
FAQ
What is CVE-2016-8738?
CVE-2016-8738 is a vulnerability with a CVSS score of 5.9 (MEDIUM). In Apache Struts 2.5 through 2.5.5, if an application allows entering a URL in a form field and the built-in URLValidator is used, it is possible to prepare a special URL which will be used to overloa...
How severe is CVE-2016-8738?
CVE-2016-8738 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8738?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Struts.